Skip to content

[APS-21171][APS-20636] bump jackson-core/databind to 2.18.9 - #87

Open
jasbir-browserstack wants to merge 1 commit into
browserstack:masterfrom
jasbir-browserstack:jasbir/aps-21171-aps-20636-jackson-2.18.9
Open

jasbir-browserstack wants to merge 1 commit into
browserstack:masterfrom
jasbir-browserstack:jasbir/aps-21171-aps-20636-jackson-2.18.9

Conversation

@jasbir-browserstack

@jasbir-browserstack jasbir-browserstack commented Oct 7, 2026 •

Copy link
Copy Markdown

Summary

Single one-line bump of the shared <jackson.version> property in pom.xml (2.18.6 → 2.18.9) closes two open P2 Jackson CVEs together:

  • APS-21171 — jackson-core async parser maxNumberLength bypass via chunked digit accumulation (GHSA-r7wm-3cxj-wff9, incomplete fix for GHSA-72hv-8253-57qq). Fixed in jackson-core 2.18.8; 2.18.9 inherits.
  • APS-20636 — jackson-databind BasicPolymorphicTypeValidator.allowIfSubTypeIsArray() allowlist bypass (GHSA-rmj7-2vxq-3g9f, CVSS 8.1). Fixed in jackson-databind 2.18.8; 2.18.9 inherits.

Why one PR, not the two open Dependabot PRs

pom.xml declares both jackson-core and jackson-databind via a single shared <jackson.version> property:

<properties>
  <jackson.version>2.18.6</jackson.version>
  ...
</properties>
...
<dependency><groupId>com.fasterxml.jackson.core</groupId><artifactId>jackson-core</artifactId><version>${jackson.version}</version></dependency>
<dependency><groupId>com.fasterxml.jackson.core</groupId><artifactId>jackson-databind</artifactId><version>${jackson.version}</version></dependency>

Dependabot PRs #85 (databind) and #86 (core) each only bump one of the two literal version strings without touching the shared property, which would leave one of core/databind pinned at the stale ${jackson.version} = 2.18.6. The clean fix is to bump the property; keeps jackson-core and jackson-databind in lockstep (Jackson maintainers' recommended practice — mismatched versions produce NoSuchMethodError at runtime).

Please close #85 and #86 as superseded if this PR is merged.

Test plan

  • CI mvn verify passes on the branch
  • No API-level changes between 2.18.6 and 2.18.9 — both are same-minor-line patch releases
  • Our Jackson usage is sync ObjectMapper.readValue only (verified: 0 hits for NonBlocking*, PolymorphicTypeValidator, allowIfSubTypeIsArray), so neither vulnerable code path is exercised by this client — but shipping the fix also protects downstream consumers who may use those APIs on top of our artifact.

Single property bump closes both CVEs in one change:

* APS-21171 — jackson-core async parser maxNumberLength bypass
  (GHSA-r7wm-3cxj-wff9, incomplete fix for GHSA-72hv-8253-57qq).
  Fixed in jackson-core 2.18.8; 2.18.9 inherits the fix.

* APS-20636 — jackson-databind BasicPolymorphicTypeValidator
  allowIfSubTypeIsArray allowlist bypass (GHSA-rmj7-2vxq-3g9f,
  CVSS 8.1). Fixed in jackson-databind 2.18.8; 2.18.9 inherits.

jackson-core and jackson-databind share one <jackson.version> property
in pom.xml, so one line bump covers both. Supersedes Dependabot PRs
browserstack#85 and browserstack#86 (which each only bumped one of the two).
@jasbir-browserstack
jasbir-browserstack requested a review from a team as a code owner October 7, 2026 04:23
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Central YAML (base), Organization UI (inherited), Workspace UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Enterprise
  • Run ID: a99dbd4e-5cc8-4dfe-a1ea-bd6e56e4e168

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant